GMX engaged Guardian to review the remediation of issues surfaced during a prior engagement in July. From the 19th of July to the 28th of July, a team of 2 auditors reviewed the source code updates.
- Published
- Review window
- July 19 to 28, 2023
- Language
- Solidity
- Chains
- Arbitrum, Avalanche
- Sector
- Perpetuals
- 0 Critical
- 0 High
- 2 Medium
- 3 Low
- 0 Informational
Scope
Overview
GMX engaged Guardian to review the remediation of issues surfaced during a prior engagement in July. From the 19th of July to the 28th of July, a team of 2 auditors reviewed the source code updates.
Findings 5
-
GSU-1 Medium Incorrect Decrease Gas Estimation Logical Error Acknowledged
Description
When estimating the gas needed for a decrease order in
estimateExecuteDecreaseOrderGasLimit, 1 is added togasPerSwapinstead of adding 1 to the swap length to account for the extra swap due todecreasePositionSwapType.Recommendation
Add 1 to the order’s swap length rather than the
gasPerSwap.Resolution
GMX Team: The recommendation will be implemented in a future release.
-
GLOBAL-1 Medium Positive Impact Misrepresented Logical Error Acknowledged
Description
During both increase and decrease orders,
forPositiveImpactis determined based upon thepriceImpactUsdbeing greater than 0, however this is based on thepriceImpactUsdafter it has been capped. In the event that the position impact pool is empty and the positive price impact value is capped to 0, the fees will be calculated with aforPositiveImpactoffalse, meanwhile the action does indeed balance the pool.Recommendation
Compute
forPositiveImpactbefore the price impact is capped so that actions that balance the pool receive the corresponding configured fees.Resolution
GMX Team: The recommendation will be implemented in a future release.
-
EDPU-1 Low Inefficient If Case Optimization Acknowledged
Description
The price impact logic is split into two
ifcases where the first one accounts for positive price impact and the second accounts for negative price impact. If the first_params.priceImpactUsd > 0condition is met, the second_params.priceImpactUsd < 0condition cannot be met, however this condition is still subsequently checked.Recommendation
Use an
else if (_params.priceImpactUsd < 0)condition to avoid checking if thepriceImpactUsdis negative if it was already found to be positive.Resolution
GMX Team: Acknowledged.
-
OCL-1 Low Outdated NatSpec Documentation Acknowledged
Description
The NatSpec does not match the struct parameters. Missing parameters include:
- info
- minBlockConfirmations
- maxRefPriceDeviationFactor
- validatedPrices
Recommendation
Update the NatSpec to reflect the struct accurately.
Resolution
GMX Team: NatSpec will be updated in a future release.
-
DPCU-1 Low Typo Typo Acknowledged
Description
“[t]he difference would be in the stored as a…” should be edited to “the difference would be stored as”.
Recommendation
Edit the comment described above.
Resolution
GMX Team: The typo will be fixed in a future release.
No findings match.
More from GMX
All 44 reportsPut your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
